SUSPICIOUS — 93658572424.pdf
SUSPICIOUS — 93658572424.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d17f3faca960ca8af72e714b0387df39b70a746aa7fabaa383fcde4d8bd1cb22 - SHA-1:
f985e1ee6b3ea112535bb4dc1907be8e4545a9f5 - MD5:
977d59e026660ffa0c828c3dddf5e149 - ssdeep:
768:QgGzpDL3XSk6WvAAW1c/EgEee6dN475BqZss/UQ+jKc7a:9GF/g9S/EgEee0475xs/UQSKaa - TLSH:
T102307DF31097ED8C7E4AAB07ADB7109D654AD78C623686A044CC772DC0B86FD2F41A61 - Submitted as: 93658572424.pdf
- File type: pdf · Size: 39156 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/e35829e6-ccdc-432f-9397-0a1768ca394b/32424154685.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=libro+de+cero+a+uno+pdf, https://uploads.strikinglycdn.com/files/e35829e6-ccdc-432f-9397-0a1768ca394b/32424154685.pdf, https://uploads.strikinglycdn.com/files/8c88bdf4-113c-4f16-a38c-195c27ab9c14/34603461974.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=libro+de+cero+a+uno+pdf
- https://uploads.strikinglycdn.com/files/e35829e6-ccdc-432f-9397-0a1768ca394b/32424154685.pdf
- https://uploads.strikinglycdn.com/files/8c88bdf4-113c-4f16-a38c-195c27ab9c14/34603461974.pdf
- https://uploads.strikinglycdn.com/files/e272a1bb-ae3d-43ac-a87a-68465aa8ff74/xowepepuxuzedezipoma.pdf
- http://files.minnisandmums.com/uploads/1/3/0/7/130775318/8423af07a08ae1.pdf
- http://files.218coopgallery.com/uploads/1/3/0/8/130813466/407fd93d0c55.pdf
- http://bululer.michaeltmeier.com/uploads/1/3/1/6/131606615/8446853.pdf
- http://jofow.revolutionsigning.com/uploads/1/3/0/7/130776644/867025ac7e6f.pdf
- http://files.pennsburydrama.com/uploads/1/3/0/7/130776401/4472202.pdf
- https://uploads.strikinglycdn.com/files/95d93ab1-3248-4215-be75-d87516694ae5/bisejudakese.pdf
- https://uploads.strikinglycdn.com/files/08cf7ce8-384e-4e6b-bf22-4c357734fe21/48764312667.pdf
- https://uploads.strikinglycdn.com/files/28942dfd-d6b9-4bb4-bac4-985b094b17f8/boponobepopawisafatose.pdf
- https://uploads.strikinglycdn.com/files/0d7402f2-16cc-4263-a5b8-67cb22e75a54/36304615460.pdf
- https://uploads.strikinglycdn.com/files/91f56e82-4eb1-4d6e-8c24-9f173e3d5f97/jetek.pdf
- https://uploads.strikinglycdn.com/files/ae3c511f-349d-451c-9c93-f1c3b78b0dd8/53047081267.pdf
- https://uploads.strikinglycdn.com/files/2b09ff42-5dc2-4dff-bb5e-7a507f613a50/vojokegukuju.pdf
- https://uploads.strikinglycdn.com/files/e53f8bf1-833e-4439-ab58-dad24b590437/67970403559.pdf
- https://uploads.strikinglycdn.com/files/bce71b29-5f31-4f88-9af5-23b5caa5e62d/57335451687.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- files.minnisandmums.com
- files.218coopgallery.com
- bululer.michaeltmeier.com
- jofow.revolutionsigning.com
- files.pennsburydrama.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report